Medium severity6.5NVD Advisory· Published Sep 28, 2026
CVE-2026-84744
CVE-2026-84744
Description
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.5.0.1 - 2.0.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.